CVE Vulnerabilities

CVE-2009-3864

Published: Nov 05, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
7.5 IMPORTANT
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The Java Update functionality in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22 and JDK and JRE 6 before Update 17, when a non-English version of Windows is used, does not retrieve available new JRE versions, which allows remote attackers to leverage vulnerabilities in older releases of this software, aka Bug Id 6869694.

Affected Software

NameVendorStart VersionEnd Version
WindowsMicrosoft**
Sun-java5Ubuntudapper*
Sun-java5Ubuntugutsy*
Sun-java5Ubuntuintrepid*
Sun-java5Ubuntujaunty*
Sun-java5Ubuntuupstream*
Sun-java6Ubuntuhardy*
Sun-java6Ubuntuintrepid*
Sun-java6Ubuntujaunty*
Sun-java6Ubuntukarmic*
Sun-java6Ubuntulucid*
Sun-java6Ubuntuupstream*

References